CVE-2026-5358

CRITICAL

Static buffer overflow in deprecated nis_local_principal

Title source: cna
STIX 2.1

Description

Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API provisional and unused. Secondly it has been discovered that the NIS+ cold start cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API can only be called with a trusted server from the pre-populated cache. The use of a trusted server means no trust boundary is crossed and this is therefore considered a normal bug.

Scores

CVSS v3 9.1
EPSS 0.0004
EPSS Percentile 12.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-120
Status published
Products (1)
The GNU C Library/glibc < 2.43
Published Apr 20, 2026
Tracked Since Apr 21, 2026